CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
398,603 CVEs
1,728 on KEV
17,267 EPSS ≥ 10%
25,086 with exploits
synced 2026-09-28
1,485 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2025-46811 EXP | A Missing Authorization vulnerability in SUSE Linux Manager allows anyone with the ability to connect to port 443 of SUSE Manager is able to run any c… | Patch early | 9.8 critical | 10.7% | 2025-07-30 |
| CVE-2015-7251 EXP | ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE have a hardcoded password of root for the root account, which allows remote attackers to o… | Patch early | 9.8 critical | 10.7% | 2015-12-30 |
| CVE-2020-6756 EXP | languageOptions.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows unauthenticated attackers to remotely execute code via the la… | Patch early | 9.8 critical | 10.6% | 2020-01-09 |
| CVE-2018-12908 EXP | Brynamics "Online Trade - Online trading and cryptocurrency investment system" allows remote attackers to obtain sensitive information via a direct re… | Patch early | 9.8 critical | 10.5% | 2018-06-27 |
| CVE-2018-14328 EXP | Brynamics "Online Trade - Online trading and cryptocurrency investment system" allows remote attackers to obtain sensitive information via a direct re… | Patch early | 9.8 critical | 10.5% | 2018-07-23 |
| CVE-2019-11703 EXP | A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in parser_get_next_char when processing certain email messages, resulting… | Patch early | 9.8 critical | 10.5% | 2019-07-23 |
| CVE-2019-11704 EXP | A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in icalmemory_strdup_and_dequote when processing certain email messages,… | Patch early | 9.8 critical | 10.5% | 2019-07-23 |
| CVE-2023-29809 EXP | SQL injection vulnerability found in Maximilian Vogt companymaps (cmaps) v.8.0 allows a remote attacker to execute arbitrary code via a crafted script… | Patch early | 9.8 critical | 10.5% | 2023-05-12 |
| CVE-2019-12765 EXP | An issue was discovered in Joomla! before 3.9.7. The CSV export of com_actionslogs is vulnerable to CSV injection. | Patch early | 9.8 critical | 10.5% | 2019-06-11 |
| CVE-2017-9811 EXP | The kluser is able to interact with the kav4fs-control binary in Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix 4 (… | Patch early | 9.8 critical | 10.5% | 2017-07-17 |
| CVE-2014-5081 EXP | sphider prior to 1.3.6, sphider-pro prior to 3.2, and sphider-plus prior to 3.2 allow authentication bypass | Patch early | 9.8 critical | 10.5% | 2020-01-10 |
| CVE-2025-4524 EXP | The Madara – Responsive and modern WordPress theme for manga sites theme for WordPress is vulnerable to Local File Inclusion in all versions up to, an… | Patch early | 9.8 critical | 10.4% | 2025-05-21 |
| CVE-2019-16692 EXP | phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter-result.php table parameter when action=add is used. | Patch early | 9.8 critical | 10.3% | 2019-09-22 |
| CVE-2019-8661 EXP | A use after free issue was addressed with improved memory management. This issue is fixed in macOS Mojave 10.14.6. A remote attacker may be able to ca… | Patch early | 9.8 critical | 10.3% | 2019-12-18 |
| CVE-2018-6228 EXP | A SQL injection vulnerability in a Trend Micro Email Encryption Gateway 5.5 policy script could allow an attacker to execute SQL commands to upload an… | Patch early | 9.8 critical | 10.2% | 2018-03-15 |
| CVE-2018-6229 EXP | A SQL injection vulnerability in an Trend Micro Email Encryption Gateway 5.5 edit policy script could allow an attacker to execute SQL commands to upl… | Patch early | 9.8 critical | 10.2% | 2018-03-15 |
| CVE-2013-6236 EXP | IZON IP 2.0.2: hard-coded password vulnerability | Patch early | 9.8 critical | 10.2% | 2020-02-12 |
| CVE-2015-7247 EXP | D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 discloses usernames, passwords, keys, values, and web account hashes (super and… | Patch early | 9.8 critical | 10.2% | 2017-04-24 |
| CVE-2018-10618 EXP | Davolink DVW-3200N all version prior to Version 1.00.06. The device generates a weak password hash that is easily cracked, allowing a remote attacker… | Patch early | 9.8 critical | 10.1% | 2018-08-01 |
| CVE-2013-2681 EXP | Cisco Linksys E4200 1.0.05 Build 7 devices contain a Security Bypass Vulnerability which could allow remote attackers to gain unauthorized access. | Patch early | 9.8 critical | 10.1% | 2020-02-05 |
| CVE-2021-30149 EXP | Composr 10.0.36 allows upload and execution of PHP files. | Patch early | 9.8 critical | 10.1% | 2021-04-06 |
| CVE-2017-11435 EXP | The Humax Wi-Fi Router model HG100R-* 2.0.6 is prone to an authentication bypass vulnerability via specially crafted requests to the management consol… | Patch early | 9.8 critical | 10.1% | 2017-07-19 |
| CVE-2014-5470 EXP | Actual Analyzer through 2014-08-29 allows code execution via shell metacharacters because untrusted input is used for part of the input data passed to… | Patch early | 9.8 critical | 10% | 2024-06-21 |
| CVE-2018-6223 EXP | A missing authentication for appliance registration vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to manipulate th… | Patch early | 9.8 critical | 10% | 2018-03-15 |
| CVE-2021-42580 EXP | Sourcecodester Online Learning System 2.0 is vunlerable to sql injection authentication bypass in admin login file (/admin/login.php) and authenticate… | Patch early | 9.8 critical | 10% | 2021-11-15 |
| CVE-2004-2761 EXP | The MD5 Message-Digest Algorithm is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as dem… | Patch early | 9.8 critical | 9.9% | 2009-01-05 |
| CVE-2018-12706 EXP | DIGISOL DG-BR4000NG devices have a Buffer Overflow via a long Authorization HTTP header. | Patch early | 9.8 critical | 9.9% | 2018-06-24 |
| CVE-2019-11705 EXP | A flaw in Thunderbird's implementation of iCal causes a stack buffer overflow in icalrecur_add_bydayrules when processing certain email messages, resu… | Patch early | 9.8 critical | 9.9% | 2019-07-23 |
| CVE-1999-1588 EXP | Buffer overflow in nlps_server in Sun Solaris x86 2.4, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code as root via a long string begi… | Patch early | 9.8 critical | 9.9% | 1999-12-31 |
| CVE-2018-6220 EXP | An arbitrary file write vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to inject arbitrary data, which may lead to… | Patch early | 9.8 critical | 9.9% | 2018-03-15 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt